ITADN

Security: vulnerable dependency image-size (CVE-2025-71329/71330) — maintained drop-in available

#57888Openlcf2212dev 创建于 18 天前
L
lcf2212devcommented
## Context This package depends on npm **`image-size`**. Upstream is **archived** and the latest release (**2.0.2**) remains affected by: - **CVE-2025-71329** — DoS via infinite loop (JXL/HEIF/JP2 zero-size boxes) - **CVE-2025-71330** — DoS via infinite loop (ICNS zero entry length) `npm audit fix` will **not** switch package names automatically. ## Maintained drop-in Community MIT fork with the same public API as `image-size@2.0.2`: - **npm:** https://www.npmjs.com/package/image-size-next (`image-size-next@2.1.0`) - **GitHub:** https://github.com/lcf2212dev/image-size-next - **Announcement:** https://github.com/lcf2212dev/image-size-next/blob/main/ANNOUNCE.md Not affiliated with the original `image-size` maintainer — honest community fork only. ## Migration options **A — Direct dependency** ```bash npm install image-size-next ``` ```diff - import { imageSize } from 'image-size' + import { imageSize } from 'image-size-next' ``` **B — Force transitive resolution (npm 8.3+)** ```json { "overrides": { "image-size": "npm:image-size-next@2.1.0" } } ``` ## Ask Happy to open a PR for **`@kohout.jakub/react-native`** if useful. Thanks for maintaining open source.
2 条评论